PatchSiren cyber security CVE debrief
CVE-2026-107604 Red Hat CVE debrief
A flaw in Keycloak's installation provider and client registration endpoints allows a realm administrator with the read-only view-clients role to access active primary secrets of confidential clients. This could enable impersonation and unauthorized access to service account permissions. The issue arises from insufficient access controls, potentially exposing sensitive client information. Affected deployments should prioritize verification and remediation efforts. The CVE Program and NVD provide official records of this vulnerability.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Realm administrators, Keycloak deployment maintainers, and security teams responsible for identity management services should be aware of this vulnerability. These stakeholders need to assess their exposure, verify remediation, and ensure that appropriate compensating controls are in place. Additionally, security teams should monitor for potential unauthorized access attempts and review system logs for signs of exploitation.
Why it matters
A realm administrator with only the read-only view-clients role can access active primary secrets of confidential clients in Keycloak, potentially leading to impersonation and unauthorized access.
- Potential impersonation of clients
- Unauthorized access to service account permissions
- Exposure of sensitive client secrets
- Verification of Keycloak deployment configurations
Technical summary
A flaw in Keycloak's installation provider and client registration endpoints allows a realm administrator with the read-only view-clients role to access active primary secrets of confidential clients. This issue arises from a lack of proper authorization checks, enabling potential impersonation and unauthorized access to service account permissions. The vulnerability is considered medium severity with a CVSS score of 4.9. Affected systems should apply patches or mitigations promptly to prevent exploitation. The vulnerability affects Keycloak's client registration and installation provider endpoints.
Defensive priority
Realm administrators and Keycloak deployment maintainers should assess exposure and verify remediation.
Recommended defensive actions
- Verify Keycloak installation provider and client registration endpoint configurations.
- Restrict access to sensitive client secrets.
- Monitor for unauthorized access attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE Program and NVD provide official records of this vulnerability. Red Hat provides additional details through their security advisory. Evidence is based on official CVE and NVD documentation, as well as Red Hat's security advisory. The vulnerability has been publicly disclosed and verified by multiple sources. No additional information is available on potential exploits or attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107604 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107604
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107604 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107604
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Keycloak-services: keycloak-services: view-clients role allows retrieval of active client secret
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107604.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-107604
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.